GROWI wiki before 7.5.5 lets anyone read files on private pages
EditorialBy TrustList Editorial
Only installations that store uploads locally are exposed. JPCERT/CC rates the flaw 6.9 on the CVSS 4.0 scale, and the vendor has released version 7.5.5 with the fix.
- Wiki
- Knowledge Management
- Cybersecurity
- Vulnerability Management
- +1 more
About GROWI wiki before 7.5.5 lets anyone read files on private pages
GROWI wiki before 7.5.5 lets anyone read files on private pages
5 October 2026: GROWI, the open-source wiki that Japanese teams use for internal documentation, has an access-control flaw that lets a remote, unauthenticated attacker read files attached to non-public pages. Versions before 7.5.5 are affected, and 7.5.5 contains the fix, according to an advisory published on Japan's JVN vulnerability portal.
Not yet independently verified. Single source: the JVN advisory, which is based on the vendor's report to JPCERT/CC. We have not read the vendor's own release notes. We will update this when it can be confirmed, and remove this note.
The flaw is tracked as CVE-2026-100727 and classed as CWE-552, files or directories accessible to external parties. JPCERT/CC lists a CVSS 4.0 base score of 6.9 and a CVSS 3.0 score of 5.3. Both reflect a network attack that needs no privileges and no user interaction, with a limited loss of confidentiality and no effect on integrity or availability.
Not every installation is exposed. The advisory says the product is affected only when the file upload setting is configured as "Local". Deployments that store uploads in an external object store rather than on the application server are therefore not described as vulnerable.
The advisory was published on 5 October. GROWI, Inc. reported the vulnerability itself to JPCERT/CC, which coordinated the disclosure with the company under Japan's Information Security Early Warning Partnership, so the notice reflects a vendor-led fix rather than an outside discovery. JVN lists the vendor's status as vulnerable, last updated on the same day.
The practical risk is about attachments, which in a team wiki often hold contracts, screenshots of internal systems and exported spreadsheets. Because the flaw works without a login, a wiki reachable from the internet is more exposed than one limited to a company network. Administrators should check whether uploads are set to Local and update to 7.5.5 or later. The advisory describes no workaround other than updating.
Company profile on TrustList: GROWI
Sources
- JVN: JVN#24352487 GROWI vulnerable to improper access control, 5 October 2026
Categories & features
- Wiki
- Knowledge Management
- Cybersecurity
- Vulnerability Management
- Japan
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More WikiThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.